#VU86273 Information disclosure in Liferay Enterprise Portal and Liferay DXP - CVE-2024-25146
Published: February 8, 2024
Liferay Enterprise Portal
Liferay DXP
Liferay
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site. A remote attacker can discover the existence of sites by enumerating URLs.